Windows – Allow Windows Domain users Local Admin rights on subset of Domain Computers

active-directorywindows

I'm a bit new to AD management, so would appreciate some help in what may be a very simple task.

I've got a domain that manages a bunch of different servers, and I want to grant local administrative rights to some domain users to some of the servers (the development webservers).

I appreciate the group concept, so I imagine I would have to create a group containing the users in question another group containing the computers to grant them access to.

What's the best way of going about this?

Best Answer

You're on the right track. Now, you would need to create an Organizational Unit in Active Directory to place the servers in question in. Then, you create and link a group policy to that OU that adds the security group that you made into the local administrators group on the server.